CFO · AI Act · 2026 Deadline

AI Act Enforcement 2026: Why the CFO Signs Off on "High-Risk AI System" Definitions

The 2026 AI Act checkpoint still lands on CFO-owned disclosure language, but the high-risk calendar changed. Article 50 transparency and GPAI enforcement remain live issues; high-risk obligations need 2027/2028 Omnibus caveats.

In brief: On 2 August 2026, Article 50 transparency obligations and Commission enforcement powers over GPAI model providers remain key checkpoints. Under the 7 May 2026 AI Omnibus political agreement, stand-alone high-risk rules move to 2 December 2027 and product-embedded high-risk rules to 2 August 2028, pending final Official Journal text. Article 99 fines still make terminology discipline a CFO disclosure issue.

The disclosure-risk problem

Article 3 defines 68 terms. Six determine whether your company faces the high-risk compliance stack: AI system, high-risk AI system, substantial modification, deployer, provider, GPAI model. A seventh, systemic risk, determines whether a GPAI model triggers Article 55 enhanced obligations that have applied since 2 August 2025 and that the Commission can enforce from 2 August 2026.

The AI Act Service Desk timeline identifies 2 August 2026 as the date when Commission enforcement powers for GPAI model providers enter into application. From that date, how your filings described your AI systems may become relevant evidence in any AI disclosure, regulator-information, or investor-disclosure review.

For SEC registrants, the principal financial officer signs Form 10-K and certifies annual and quarterly reports; investor materials should be controlled through the disclosure process when they discuss material AI claims. If risk privately classifies a production model as high-risk while MD&A calls it "automated decision support", filing and internal assessment disagree. In April 2025, the SEC and DOJ charged Albert Saniger, former CEO of Nate, Inc., over alleged false AI automation claims; the SEC alleged Nate relied substantially on contract employees to manually input orders.

The stakes

Article 99 establishes three fine tiers. Higher of a euro cap or percentage of worldwide turnover applies to undertakings. For SMEs, the lower of the two applies.

#TierTriggerCap (euro)Cap (% worldwide turnover)
1Tier 1Prohibited AI practices (Article 5)EUR 35,000,0007%
2Tier 2Provider, authorized rep, importer, distributor, deployer, notified body, transparency obligations (Art. 16, 22, 23, 24, 26, 31, 33, 34, 50)EUR 15,000,0003%
3Tier 3Incorrect or misleading information to authoritiesEUR 7,500,0001%

Tier 2 attaches to the operator and transparency obligations that attach once an AI system is in scope as high-risk or subject to Art. 50 transparency rules. If production docs call a system a "model" while the risk register calls it a "high-risk AI system" and the 10-K calls it "AI-powered automation", the definitional drift is an evidentiary problem. Tier 3 attaches separately: if the regulator asks for your classification rationale and receives inconsistent documents, the "incorrect or misleading information" tier may apply.

The practical CFO question is what evidence exists that AI claims were reviewed before they reached investor-facing or regulator-facing materials. A glossary is not a formal legal defense; it is one process artifact showing who approved which term, when, and against which regulatory definition.

The 2026 checkpoint and EU market scope

The AI Act applies in phases:

Use the current calendar, not the old countdown. After the AI Omnibus political agreement, the CFO should separate 2026 Article 50/GPAI enforcement from 2027/2028 high-risk planning. Each disclosure, inventory, and technical-documentation workstream still needs consistent Article 3 terminology to be internally coherent. Terminology discipline supports — it does not replace — Article 9/11/17 conformity assessment.

How terminology governance addresses this

Compliance Glossary is not a GRC platform and does not replace risk management or conformity assessment. It provides one artifact: a governed, four-eyes-approved, audit-trailed glossary of the terms that appear in every AI Act deliverable and external disclosure. The 68 Article 3 definitions are available through the AI Act glossary packet.

The outcome: MD&A, internal risk register, Article 11 technical documentation, and investor-deck language all reference the same governed definitions, approved by two people, with a complete change history. That is the defensible AI-disclosure record the 2026 enforcement wave will test.

Compliance Glossary is not a substitute for SOX disclosure controls, ICFR, or a GRC platform.

For current pricing, see the Atlassian Marketplace.

Frequently asked questions

Why does the CFO personally sign off on AI Act terminology?

For SEC registrants, the principal financial officer signs Form 10-K and certifies annual and quarterly reports. Investor materials should be controlled through the disclosure process when they discuss material AI claims. If filings describe a system as ordinary software while internal materials classify it differently, the inconsistency is a disclosure-control issue.

What are the AI Act fine tiers?

Article 99 sets three tiers (higher of cap or turnover percentage). Tier 1 prohibited practices: EUR 35 million or 7% of global turnover. Tier 2 covers provider, authorized rep, importer, distributor, deployer, notified body, and transparency obligations (Art. 16, 22, 23, 24, 26, 31, 33, 34, 50) at EUR 15 million or 3%. Tier 3 for incorrect or misleading information to authorities: EUR 7.5 million or 1%. SMEs pay the lower of the two.

What changes on 2 August 2026?

After the AI Omnibus political agreement, 2 August 2026 is best treated as a narrower checkpoint: Article 50 transparency obligations and Commission enforcement powers for GPAI model providers. Stand-alone high-risk AI rules move to 2 December 2027 and product-embedded high-risk rules to 2 August 2028 as planning dates pending final legal text. Prohibitions applied from 2 February 2025; GPAI obligations applied from 2 August 2025.

How does a terminology glossary reduce AI disclosure risk?

High-risk AI system, substantial modification, deployer, provider, GPAI model, and systemic risk each have Article 3 definitions that determine which obligations apply. A shared, approved, audit-trailed glossary records who approved which wording, when, and against which regulatory text — reasonable-care evidence at the individual-liability level the SEC has flagged.

This article is informational and is not legal advice. Consult qualified counsel for AI Act compliance decisions specific to your facts.

Sources checked

Get the 68 Article 3 definitions into governance before the next AI Act checkpoint

For current pricing, see the Atlassian Marketplace.

Evaluate in Confluence Read the Security Whitepaper

Related reading